Categories: Business

Here’s how you can find out if your credentials have been leaked online

  • This is a 104 GB file containing email addresses and passwords.

  • The Pwned Passwords platform allows users to check if they have been affected

We live in a digital world where we have numerous accounts. We are listed on email platforms, online stores, streaming services, mobile apps and many more. And over the years, we accumulate more and more usernames and passwords.

Although we often feel secure, there is a distinct possibility that some of our credentials will eventually be compromised. In general terms, this could be due to an incident on our end, involving users, or involving companies we trust.

Millions of passwords on the forum

Data leaks are an unfortunate reality. Over the years we have seen collections circulating among millions of passwords

which prompted Google and Microsoft to add tools to check whether passwords stored in the browser have been compromised.


This week, a massive new collection of leaked data surfaced and is being distributed for free on forums frequented by cybercriminals. That’s 71 million email addresses and 100 million passwords stored in plain text.

The leak was discovered by Troy Hunt, a renowned cybersecurity analyst who created this page many years ago. I was banned to help identify data leaks. Hunt explains that he took a sample of the huge 104GB file to get some details about it.

Capture part of the collected data

After extensive testing, some of which involved victims, he concluded that the compilation contained real email addresses and passwords, although with one twist: it seemed to contain a lot of old passwords.

Hunt also found that 67% of the data was already included in I Been Pwned, but the remaining 33% were completely new. Either way, that’s millions of passwords that are available to cybercriminals, and in some scenarios this problem can become more complex.

Passwords page

While some services prompt users to change their passwords after a certain time, others do nothing about it. In this sense, it is likely that people whose keys are many years old were affected. But this is not the only problem.

Password reuse also comes into play, a very common practice that attackers can take advantage of. Since email addresses were also exposed, reusable password an information leak could open the door to breaching the security of other services.

As we speak, all the leaked passwords have been added to a service called Pwned Passwords, which allows users to check if they have been stolen. It’s an open source tool from the creators of Have I Been Pwned that promises to protect your privacy.

Pwned Passwords works on the same mechanics as Have I Been Pwned. It should be noted that although it is designed famous actors from the world of cybersecurity, and details of the project are publicly available, users should use this tool at their own risk.

Images: Mika Baumeister | Troy Hunt

In Hatak: someone received 1.8 million euros in cryptocurrency thanks to “cryptojacking”: he was eventually arrested by Europol

Source link

Admin

Share
Published by
Admin

Recent Posts

PHOTO – Angelina Jolie, rare appearance with her son Knox, 16 years old: c’est son sosie!

At 16, Knox made a prominent appearance on red carpets. Today, November 17, the Hollywood…

7 minutes ago

Kremlin, after US authorization to Ukraine to use its weapons in attacks against Russia: “increases tensions”

The Kremlin has warned that if the United States allows Ukraine to use its weapons…

11 minutes ago

More than 20% of treatments recommended by the European Society of Oncology are unfunded.

Two out of ten treatments recommended by the European Society of Medical Oncology (ESMO) have…

13 minutes ago

Grifols shares fall due to Brookfield offer

Grifols shares (GRF.ES), fell by 3% after the publication of information that Brookfield plans to…

20 minutes ago

35,000-year-old saber-tooth calf found with intact head

Subscribe to National Geographic for just 1 euro per month for 6 months. For a…

23 minutes ago

Viña Albali Valdepenas announces the end of David Ramos as coach | LNFS

Viña Albali Valdepenas announced the dismissal of David Ramos as first team coach, ending a…

24 minutes ago